2014年11月28日星期五

Cisco Catalyst 2960 Switches Price below USD500.00 in 3Anetwork



The Cisco Catalyst 2960 Switches are the leading Layer 2 edge, providing improved ease of use, highly secure business operations, improved sustainability, and a borderless network experience. 2960 Series are fixed-configuration access switches designed for enterprise, midmarket, and branch office networks to provide lower total cost of ownership.

There are 4 types of Cisco Catalyst 2960 Series Switches which the price is below USD500.00 in 3Anetwork: Cisco WS-C2960-24TT-L, WS-C2960-24TC-L, WS-C2960-8TC-L, WS-C2960-8TC-S and WS-C2960-24TC-S.

WS-C2960-24TT-L Overview
l  Layer 2 access switch
l  Software: LAN Base
l  Total 24 Ethernet 10/100 ports
l  2x1000 BT uplinks
l  Non-PoE switch
l  Support redundant power supply (RPS)
l  Support ACL, Auto QoS, DHCP Snooping, Link STate Tracking, and IPv6 Host
l  Not support FlexStack
l  Forwarding bandwidth: 16Gbps
l  Switching bandwidth: 32Gbps
l  USD465.00

WS-C2960-24TC-L Overview
l  Layer 2 access switch
l  Software: LAN Base
l  Total 24 Ethernet 10/100 ports
l  2 GE dual purpose uplink
l  Support redundant power supply (RPS)
l  Support ACL, Auto QoS, DHCP Snooping, Link STate Tracking, and IPv6 Host
l  Not support FlexStack
l  If optical ports to be used, additional GE SFP module will be required
l  Forwarding bandwidth: 16Gbps
l  Switching bandwidth: 32Gbps
l  USD460.00

WS-C2960-8TC-L Overview
l  Layer 2 access switch
l  Software: LAN Base
l  Total 8 Ethernet 10/100 ports
l  1 GE dual purpose uplink
l  Non-PoE switch
l  Not support redundant power supply (RPS)
l  Support ACL, Auto QoS, DHCP Snooping, Link STate Tracking, and IPv6 Host
l  Not support FlexStack
l  If optical ports to be used, additional GE SFP module will be required
l  Compact size with no fan
l  Forwarding bandwidth: 16Gbps
l  Switching bandwidth: 32Gbps

WS-C2960-8TC-S Overview
l  Entry layer 2 access switch
l  Software: LAN Lite
l  Total 8 Ethernet 10/100 ports
l  1 GE dual purpose uplink
l  Non-PoE switch
l  Not support FlexStack
l  Not support redundant power supply (RPS)
l  Not support ACL, Auto QoS, DHCP Snooping, Link STate Tracking, and IPv6 Host
l  If optical ports to be used, additional GE SFP module will be required
l  Compact size with no fan
l  Forwarding bandwidth: 16Gbps
l  Switching bandwidth: 32Gbps
l  USD357.00

WS-C2960-24TC-S Overview
l  Entry layer 2 access switch
l  Software: LAN Lite
l  Total 24 Ethernet 10/100 ports
l  2 GE dual purpose uplink
l  Non-PoE switch
l  Not support FlexStack
l  Not support redundant power supply (RPS)
l  Not support ACL, Auto QoS, DHCP Snooping, Link STate Tracking, and IPv6 Host
l  If optical ports to be used, additional GE SFP module will be required
l  Forwarding bandwidth: 16Gbps
l  Switching bandwidth: 32Gbps
l  USD435.00

As a world leading Cisco networking products supplier, 3Anetwork wholesales original new Cisco networking equipments, including Cisco Catalyst switches, Cisco routers, Cisco firewalls, Cisco wireless products, Cisco modules and interface cards products, 3Anetwork.com are most competitive on Cisco switches, like Cisco 2960 switches, Cisco 3560V2 3560X switches, Cisco 3750V2 3750X switches. If you have such requirement please contact your sales person, if you are new customer, please feel free to contact info@3anetwork.com. Our CCIE headed technical team can provide network design, products installation and configuration, trouble shooting etc.

More related topics

2014年11月21日星期五

Cisco Catalyst 2960-X Switches NetFlow-Lite Overview



What is NetFlow-Lite?

NetFlow-Lite on Cisco Catalyst 2960-X switches collects packets randomly, classifies them into flows, and measures flow statistics as they pass through the switch. It is a true flow-based traffic-monitoring mechanism that conserves valuable forwarding bandwidth when exporting flow-based data for analysis and reporting. This export data provides visibility into traffic that is switched through the Cisco Catalyst 2960X and Catalyst 2960XR Switches.
The Cisco Catalyst 2960-X has been tested with the leading NetFlow collector applications such as Cisco Prime, ActionPacked LiveAction, Plixer Scrutinizer, and many more. 

What is NetFlow-Lite Used for?
NetFlow-Lite offers network administrators and engineers the following capabilities:
l  Unprecedented visibility: NetFlow-Lite provides real-time information about traffic flows from endpoints such as PCs, phones, IP cameras, etc. You can use this information for traffic monitoring of Layer 2 and Layer 3 traffic as well as capacity planning.
l  Network planning: You can use NetFlow-Lite to capture data over a long period of time so that customers can understand traffic patterns, top talkers, top applications, etc. This feature provides accurate data to track and anticipate network growth and plan upgrades.
l  Simplified troubleshooting: You can use NetFlow-Lite flow-based analysis techniques to understand traffic patterns, which can help in proactively detecting problems, troubleshooting efficiently, and resolving problems quickly.

NetFlow-Lite Capabilities
NetFlow-Lite provides a granular packet-sampling mechanism that is adjustable up to 1:32 and available for all interfaces. The implication is that a subset of all packets passing through the Cisco Catalyst 2960X or Catalyst 2960XR will be selected for reporting. Figure 2 shows some of the data gathered by Cisco NetFlow-Lite.

Output from Cisco NetFlow-Lite




NetFlow-Lite on the Cisco Catalyst 2960-X has the following capabilities:
l  NetFlow-Lite is supported on all downlink and uplink ports.
l  NetFlow-Lite is natively available with no additional hardware required.
l  The sampling range is from 1:32 to 1:1022.
l  The application measures 16,000 flows per switch.
l  Physical ports and VLAN Interfaces (switched virtual interfaces [SVI]) are supported.
l  NetFlow-Lite on the Cisco Catalyst 2960-X supports ingress flows only.
l  Export using standards-based IP Information export (IPFIX) or Version 9 record format.

Differences between Flexible NetFlow-Lite, Flexible NetFlow, and sFlow
Differences between NetFlow-Lite, Flexible NetFlow, and sFlow


Note
Product support of sFlow may vary.

Cisco Catalyst 2960-X Series Switches are the next generation of the world's most widely deployed access switches, providing Layer 2 and Layer 3 access features. The switches deliver best-in-class energy efficiency, while preserving your investments through mixed stacking with existing Catalyst 2960-S and SF switches.
As a world leading Cisco networking products supplier, 3Anetwork keeps stock in Cisco 2960-X series switches, and save up to 65%.

Our website: http://www.3anetwork.com
Telephone: +852-3069-7733
Email:  info@3Anetwork.com
Address: 23/F Lucky Plaza, 315-321 Lockhart Road, Wanchai, Hongkong

More related topics

2014年7月16日星期三

Cisco 2921 Integrated Services Router

Cisco 2921 Integrated Services Router is one type of Cisco 2900 Series Integrated Services Routers (ISR). Cisco 2900 series routers are designed to meet the application demands of today's medium-sized branches and to evolve to cloud-based services. They deliver virtualized applications and highly secure collaboration through the widest array of WAN connectivity at high performance that offers concurrent services at up to 75 Mbps. All Cisco 2900 Series Integrated Services Routers (ISR) have modular design that allows for reuse of a broad array of existing modules that meet business requirements while maximizing investment protection.

The Cisco 2921 delivers highly secure data, voice, video, and application services for small offices.

Features
  • 3 Integrated 10/100/1000 Ethernet ports with 1 port capable of RJ-45 or SFP connectivity
  • 1 service module slot
  • 4 Enhanced High-Speed WAN Interface Card (EHWIC) slots
  • 3 onboard digital signal processor slots
  • 1 internal service module slot for application services
  • Fully integrated power distribution to modules supporting 802.3af Power over Ethernet (PoE) and Cisco Enhanced PoE
  • Security
    • Embedded hardware-accelerated VPN encryption
    • Secure collaborative communications with Group Encrypted Transport VPN, Dynamic Multipoint VPN, or Enhanced Easy VPN
    • Integrated threat control using Cisco IOS Firewall, Cisco IOS Zone-Based Firewall, Cisco IOS IPS, and Cisco IOS Content Filtering
    • Identity management: Intelligently protecting endpoints using authentication, authorization, and accounting (AAA), and public key infrastructure
  • Voice
    • High-density packet voice DSP module, optimized for voice and video support
    • Standards-certified VoiceXML browser services
    • Cisco Unified Border Element capabilities
    • Cisco Unity Express voicemail support
    • Support for Cisco Communications Manager Express and Survivable Remote Site Telephony

The Cisco 2900 Series offer unparalleled total cost of ownership savings and network agility through the intelligent integration of market leading security, unified communications, wireless, and application services. The Integrated Services Routers Generation 2 platforms are future-enabled with multi-core CPUs, support for high capacity DSPs (Digital Signal Processors) for future enhanced video capabilities, high powered service modules with improved availability, Gigabit Ethernet switching with enhanced POE, and new energy monitoring and control capabilities while enhancing overall system performance.

3Anetwork.com wholesales Cisco 2900 series routers, ship to worldwide. For the rich experience, among all Cisco 2900 routers, cisco2901/K9cisco2911/K9 and cisco2921/K9 are best selling models. You can log in www.3anetwork.com for more details.

More related topics

2014年5月30日星期五

How to Set Switches on the IP-MAC Binding

Although in the TCP / IP networks, computers often need to set the IP address to communicate, in fact, the communication between computers is not via IP address, but by means of the MAC address of the network card. IP addresses only to be used to query the MAC address of the target computer which is to communicate.   

ARP protocol is used to notify corresponding MAC address of our own IP for other's computers, network equipment. There are one or more tables in the computer's cache ARJ for storing IP address and parsed Ethernet MAC address. The corresponding MAC address will retain in the ARP cache after one computer was communicated with another IP address computer. So the next time when communicate with the same IP address, it will use the cache MAC addresses directly instead of querying the MAC address.

Under a switched network, the switch also maintains a MAC address table, and then sends data to the target computer according to MAC address. 

Why do we need to bind MAC and IP Address? IP address is very easy to modify while MAC address is stored in the EEPROM of the card, and only the card's MAC address is determined. Therefore, in order to prevent insider from doing illegal IP embezzlement (for example: embezzle the higher IP address authority to get the information outside the permission) we can bind the internal network IP address and MAC address, and the embezzlement will be failed due to the unmatched MAC address even if the embezzler changed the IP address. What’s more, we can find corresponding user of the network card according to the MAC address and then find out the embezzler due to the only certainty of MAC address.

Currently, the MAC address and IP address binding techniques has been adopted to the internal network of many companies. Here we will introduce the IP and MAC binding programs of the Cisco switch.

There are three options as below to choose as to the Cisco, and the function of option 1 and 2 is the same, that is to say, bind the specific host MAC address (network card hardware address) to the specific switch port. Option 3 is simultaneously binding the specific host MAC address (network card hardware address) and IP address to the specific host port on the switch.

Option 1 - Based on MAC address binding on port

Take Cisco 2950 switch for example, to log into the switch, enter the administrative password into the configuration mode, and then input the command:

Switch#config terminal
Enter into the configuration mode
Switch(config)# Interface fastethernet 0/1
Enter into the specific port configuration mode
Switch(config-if)#Switchport port-secruity
Configure port security mode
Switch(config-if )switchport port-security mac-address MAC (MAC address of the mainframe)
Configure the port to bind the host's MAC address
Switch(config-if )no switchport port-security mac-address MAC (MAC address of the host computer)
Delete the binding host's MAC address

Note:
These functions apply to Cisco 2950,3550,4500,6500 Series Switches

Option 2 - based on extended access lists of MAC addresses

Switch(config)Mac access-list extended MAC10
 Define a MAC address access control list and name the list to be MAC10  
Switch(config)permit host 0009.6bc4.d4bf any
Define the host MAC address 0009.6bc4.d4bf  to access any host computers
Switch(config)permit any host 0009.6bc4.d4bf
Define all host computers to access the host MAC address 0009.6bc4.d4bf
Switch(config-if )interface Fa0/20
# Enter into specific interface configuration mode
Switch(config-if )mac access-group MAC10 in
Apply to access list with the name of MAC 10 on the port (that is the access policies we defined before)
Switch(config)no mac access-list extended MAC10
Clear the access list which named MAC 10

Note:
The above functions can be achieved on Cisco 2960,3560,4500,6500 Series switches, however, the 2960, 3560 switches need the Enhanced Image.



Only the combination between option 1 or 2 and the based ACL (access control lists) of IP can achieve the IP-MAC binding function.   
Switch(config)Mac access-list extended MAC10
Define a MAC address access control list and name the list to be MAC10
Switch(config)permit host 0009.6bc4.d4bf any
Define the host MAC address 0009.6bc4.d4bf  to access any host computers
Switch(config)permit any host 0009.6bc4.d4bf
Define all host computers to access the host MAC address 0009.6bc4.d4bf
Switch(config)Ip access-list extended IP10
Define a IP address access control list and name the list to be IP10
Switch(config)Permit 192.168.0.1 0.0.0.0 any
Define the host of 192.168.0.1 IP address to access any host computers
Permit any 192.168.0.1 0.0.0.0
Define all host computers to access the host of 192.168.0.1 IP address
Switch(config-if )interface Fa0/20
# Enter into specific interface configuration mode
Switch(config-if )mac access-group MAC10 in
Apply to access list with the name of MAC 10 on the port (that is the access policies we defined before)
Switch(config-if )Ip access-group IP10 in
Apply to access list with the name of IP10 on the port (that is the access policies we defined before)
Switch(config)no mac access-list extended MAC10
Clear the access list which named MAC10
Switch(config)no Ip access-group IP10 in
Clear the access list which na med IP10

The above mentioned option 1 is based on the binding between MAC address of host computer and switch ports, Option 2 is based on the MAC address access control list, the functions of the first two schemes can be achieved the same. The IP and MAC address binding can be achieved if you do as the Option 3. You can combine Option 1 or 2 with ACL (access control lists) to realize what you want.

Note:
The above functions can be achieved on Cisco 2960,3560,4500,6500 Series switches, however, the 2960, 3560 switches need the Enhanced Image.

Note:

Apparently, the binding between MAC address and IP address can avoid embezzlement of internal IP addresses, however, in fact, there are a lot of defects between the binding and can not really avoid the embezzlement of the internal IP addresses due to the layers of protocols and network card drivers and other technologies.

More related:

FAQ for Cisco Integrated Services Router Generation 2